r2frida icon indicating copy to clipboard operation
r2frida copied to clipboard

command pdf can not work properly

Open BurningTeng opened this issue 5 years ago • 7 comments

  1. Attach process r2 frida://BH93001BDE/com.asp.lovevideo
  2. Using \iE libImSDK.so~nativeDoBackground
  3. Using command pdf Error message is shown as below: p: Cannot find function at 0x76fdd59314
  4. Using pd, it can work

burning

BurningTeng avatar Nov 24 '20 17:11 BurningTeng

You need to analyze function (af) before doing pdf

s offset
af
pdf // or pdg (if you installed r2ghidra-dec)

enovella avatar Nov 24 '20 17:11 enovella

I tried pdz related to r2retdec. It does not work. I will try pdz later.

[0x76fdd59318]> pdz decompilation error: Failed to load input file

BurningTeng avatar Nov 24 '20 17:11 BurningTeng

pdz is not a valid command. why do you want to use pdz?

On 24 Nov 2020, at 18:15, BurningTeng [email protected] wrote:

I tried pdz. It does not work. I will try pdz later.

[0x76fdd59318]> pdz decompilation error: Failed to load input file

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/nowsecure/r2frida/issues/277#issuecomment-733119029, or unsubscribe https://github.com/notifications/unsubscribe-auth/ABRCGG6PA5QIVYY7TMQTM2LSRPS35ANCNFSM4UBE7XVA.

trufae avatar Nov 24 '20 18:11 trufae

Command pdz is a command which is provided by r2Retdec plugin. It does not work.

I have tried pdg for decompiling. It works well. But when I use command pdf, following message will show. What is the meaning of following message? Linear size differs too much from the bbsum, please use pdr instead. Command pdr and pdg works well. burning

BurningTeng avatar Nov 25 '20 01:11 BurningTeng

Try with r2ghidra-dec:

$ r2pm -ci r2ghidra-dec
$ r2 frida://BH93001BDE/com.asp.lovevideo
s `\iE @ libImSDK.so~+nativeDoBackground`
af
pdg

enovella avatar Nov 25 '20 09:11 enovella

Thanks very much. pdg works well.

But when I use command pdf, following message will show. What is the meaning of following message? Linear size differs too much from the bbsum, please use pdr instead.

burning

BurningTeng avatar Nov 25 '20 10:11 BurningTeng

I have another question, Is there any method to make first parameter to be type JNIEnv? burning

BurningTeng avatar Nov 25 '20 11:11 BurningTeng

this is an issue in r2 not r2frida, lets move the issue in the other project instead

trufae avatar Feb 04 '24 08:02 trufae